Video 12 · Becoming a HIPAA Qualified Expert

12. Running an Engagement: Scoping to Mitigation

37 min

After this video you can

  • Name the seven engagement phases
  • Scope, classify, and assess context
  • Run mitigation to a passing result
  • Verify the file before you sign

Module 7: Practice · Runtime 37:29 · YouTube title: Running a HIPAA Expert Determination Engagement, Start to End

This is what the job looks like, from first client call to final number. The seven-phase risk-based lifecycle, walked on the Apex Health composite engagement: scoping, field classification and the free-text problem, context assessment, baseline measurement, two rounds of mitigation, the negotiation, the utility check, and verification before signing.

The seven-phase lifecycle

  1. Describe the data situation and the release context
  2. Data inspection and field classification
  3. Context risk assessment
  4. Threat modeling and data risk measurement
  5. Overall risk = data risk × context risk
  6. Determine and justify the threshold, before results are known
  7. Mitigate, transform, and re-measure until the number clears; then report, then refresh

Every phase leaves an artifact: a scoping memo, a data dictionary, a context evidence file, a measurement log, a transformation specification. Those artifacts are the raw material of the report.

In this video

  • Scoping: covered entity or business associate, one-time release or recurring feed, who the anticipated recipients are, public or controlled
  • Apex Health: 50,000 longitudinal oncology records, pharma partner, air-gapped enclave, DUA; prosecutor model, context 0.05, threshold 0.05
  • Classification, rare tumor codes as quasi-identifiers, NLP redaction of notes followed by manual sampling
  • Context assessment: security posture, DUA terms, plausible adversaries, external data environment
  • Round one: baseline 0.20 × 0.05 = 0.01, already under threshold, and mitigation proceeded anyway
  • Round two: date shift ±15 days, ZIP5 to ZIP3, ICD rollup, suppression of about 0.4 percent; data risk 0.04, overall 0.002
  • The negotiation: declining the rollback with alternatives
  • The utility check you owe the recipient, verification before you sign, and El Emam versus HITRUST as two frameworks around the math

Authorities quoted on screen

the risk-based methodology associated with El Emam's work; the HITRUST De-Identification Framework, harmonized with the NIST Cybersecurity Framework.

Key takeaways

  • Scope and context define the opinion; both become limitation language.
  • Mitigation is a measured loop, and judgment does not stop at the first passing number.
  • Verify the delivered file yourself before you sign anything.

Coming next: Video 13, The Determination Report and Liability

The report is the product, not the data transformation. All ten sections of the technical report are drafted in prose, each traced to an authority, followed by the seven-part attestation letter with sample language, validity periods and refresh triggers, the contractual envelope, liability and insurance, independence, disclosure review boards, and how a determination gets tested.

Saved in your browser only — no account, no server.